CVE-2023-4703

CVE-2023-4703: All in One B2B for WooCommerce <= 1.0.3 - Unauthenticated Privilege Escalation

Vendor Unknown
Product All in One B2B for WooCommerce
Published January 16, 2024
Last update June 20, 2025

CVSS base score

What the vulnerability does

01Description

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

Key dates

02Disclosure timeline

January 16, 2024 CVE published
June 20, 2025 Record updated